Описание
The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance.
This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.
A flaw was found in the mod_auth module of OTP's inets httpd server. When configured with multiple directory configuration blocks and using dets or mnesia authentication backends, the module incorrectly collapses all directory blocks into a single shared user/group namespace. This allows a user authenticated for one protected directory to gain unauthorized access to other protected directories on the same server instance, leading to an authentication bypass.
Отчет
Moderate: The mod_auth module in the inets httpd server, as shipped in Red Hat Hardened Images, is vulnerable to an authentication bypass. This flaw occurs when the server is configured with dets or mnesia authentication backends and multiple directory blocks with differing access requirements, leading to a collapse of user/group namespaces. An authenticated user for one protected directory can then access other protected directories on the same server instance, undermining intended access controls.
Меры по смягчению последствий
To mitigate this issue, avoid configuring the inets httpd server's mod_auth module with dets or mnesia authentication backends when using multiple directory blocks that require distinct user or group populations. Alternatively, ensure that all protected directories are intended to share identical user populations, thereby eliminating reliance on namespace isolation. If possible, switch to the plain authentication backend, which correctly isolates per-directory users and groups.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | cryostat/cryostat-storage-rhel9 | Not affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/volsync-rhel9 | Not affected | ||
| Red Hat OpenShift Dev Spaces | devspaces/traefik-rhel9 | Not affected | ||
| Red Hat Hardened Images | erlang27-main-27.3.4.17-0.1.hum1 | Fixed | RHSA-2026:62531 | 02.09.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.
The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blocks, collapses all directory blocks into a single shared user/group namespace. A user added to one protected directory is accepted as valid for all other protected directories on the same server instance. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to inets from 5.10 before 9.3.2.7, from 9.4 before 9.6.2.3, and from 9.7 before 9.7.2. Whether OTP before OTP 17.0, corresponding to inets before 5.10, is affected is unknown.
inets, httpd: Authentication Bypass via Directory Namespace Collapse in httpd mod_auth
The mod_auth module in OTP's inets httpd server, when configured with ...
6.5 Medium
CVSS3